|
| 1 | +#!/usr/bin/env python |
| 2 | +# -*- coding: utf-8 -*- |
| 3 | +from pathutils import dotname, full_path |
| 4 | + |
| 5 | +from pytest import raises |
| 6 | + |
| 7 | +from saml2 import xmldsig as ds |
| 8 | +from saml2.config import config_factory |
| 9 | +from saml2.response import VerificationError |
| 10 | +from saml2.response import authn_response |
| 11 | + |
| 12 | + |
| 13 | +HOLDER_OF_KEY_RESPONSE_FILE = full_path("saml_hok.xml") |
| 14 | +INVALID_HOLDER_OF_KEY_RESPONSE_FILE = full_path("saml_hok_invalid.xml") |
| 15 | + |
| 16 | + |
| 17 | +class TestHolderOfKeyResponse: |
| 18 | + def test_valid_hok_response_is_parsed(self): |
| 19 | + """Verifies that response with 'holder-of-key' subject confirmations is parsed successfully.""" |
| 20 | + resp = self._get_test_response(HOLDER_OF_KEY_RESPONSE_FILE) |
| 21 | + resp.do_not_verify = True |
| 22 | + resp.parse_assertion() |
| 23 | + assert resp.get_subject() is not None |
| 24 | + assert len(resp.assertion.subject.subject_confirmation) == 2 |
| 25 | + |
| 26 | + actual_hok_certs = [ |
| 27 | + ki.x509_data[0].x509_certificate.text.strip() |
| 28 | + for sc in resp.assertion.subject.subject_confirmation |
| 29 | + for ki in sc.subject_confirmation_data.extensions_as_elements( |
| 30 | + ds.KeyInfo.c_tag, ds |
| 31 | + ) |
| 32 | + ] |
| 33 | + assert actual_hok_certs == self._expected_hok_certs() |
| 34 | + |
| 35 | + def _expected_hok_certs(self): |
| 36 | + certs = [ |
| 37 | + ( |
| 38 | + "MIICITCCAYoCAQEwDQYJKoZIhvcNAQELBQAwWDELMAkGA1UEBhMCenoxCzAJBgNV" |
| 39 | + "BAgMAnp6MQ0wCwYDVQQHDAR6enp6MQ4wDAYDVQQKDAVaenp6ejEOMAwGA1UECwwF" |
| 40 | + "Wnp6enoxDTALBgNVBAMMBHRlc3QwIBcNMTkwNDEyMTk1MDM0WhgPMzAxODA4MTMx" |
| 41 | + "OTUwMzRaMFgxCzAJBgNVBAYTAnp6MQswCQYDVQQIDAJ6ejENMAsGA1UEBwwEenp6" |
| 42 | + "ejEOMAwGA1UECgwFWnp6enoxDjAMBgNVBAsMBVp6enp6MQ0wCwYDVQQDDAR0ZXN0" |
| 43 | + "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDHcj80WU/XBsd9FlyQmfjPUdfm" |
| 44 | + "edhCFDd6TEQmZNNqP/UG+VkGa+BXjRIHMfic/WxPTbGhCjv68ci0UDNomUXagFex" |
| 45 | + "LGNpkwa7+CRVtoc/1xgq+ySE6M4nhcCutScoxNvWNn5eSQ66i3U0sTv91MgsXxqE" |
| 46 | + "dTaiZg0BIufEc3dueQIDAQABMA0GCSqGSIb3DQEBCwUAA4GBAGUV5B+USHvaRa8k" |
| 47 | + "gCNJSuNpo6ARlv0ekrk8bbdNRBiEUdCMyoGJFfuM9K0zybX6Vr25wai3nvaog294" |
| 48 | + "Vx/jWjX2g5SDbjItH6VGy6C9GCGf1A07VxFRCfJn5tA9HuJjPKiE+g/BmrV5N4Ce" |
| 49 | + "alzFxPHWYkNOzoRU8qI7OqUai1kL" |
| 50 | + ), |
| 51 | + ( |
| 52 | + "MIICITCCAYoCAQEwDQYJKoZIhvcNAQELBQAwWDELMAkGA1UEBhMCenoxCzAJBgNV" |
| 53 | + "BAgMAnp6MQ0wCwYDVQQHDAR6enp6MQ4wDAYDVQQKDAVaenp6ejEOMAwGA1UECwwF" |
| 54 | + "Wnp6enoxDTALBgNVBAMMBHRlc3QwIBcNMTkwNDEyMTk1MDM0WhgPMzAxODA4MTMx" |
| 55 | + "OTUwMzRaMFgxCzAJBgNVBAYTAnp6MQswCQYDVQQIDAJ6ejENMAsGA1UEBwwEenp6" |
| 56 | + "ejEOMAwGA1UECgwFWnp6enoxDjAMBgNVBAsMBVp6enp6MQ0wCwYDVQQDDAR0ZXN0" |
| 57 | + "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDjW0kJM+4baWKtvO24ZsGXNvNK" |
| 58 | + "KkwTMz7OW5Z6BRqhSOq2WA0c5NCpMk6rD8Z2OTFEolPojEjf8dVyd/Ds/hrjFKQv" |
| 59 | + "8wQgbdXLN51YTIsgd6h+hBJO+vzhl0PT4aT7M0JKo5ALtS6qk4tsworW2BnwyvsG" |
| 60 | + "SAinwfeWt4t/b1J3kwIDAQABMA0GCSqGSIb3DQEBCwUAA4GBAFtj7WArQQBugmh/" |
| 61 | + "KQjjlfTQ5A052QeXfgTyO9vv1S6MRIi7qgiaEv49cGXnJv/TWbySkMKObPMUApjg" |
| 62 | + "6z8PqcxuShew5FCTkNvwhABFPiyu0fUj3e2FEPHfsBu76jz4ugtmhUqjqhzwFY9c" |
| 63 | + "tnWRkkl6J0AjM3LnHOSgjNIclDZG" |
| 64 | + ), |
| 65 | + ] |
| 66 | + return certs |
| 67 | + |
| 68 | + def test_invalid_hok_response_fails_verification(self): |
| 69 | + """Verifies that response with invalid 'holder-of-key' subject confirmations is parsed successfully.""" |
| 70 | + resp = self._get_test_response(INVALID_HOLDER_OF_KEY_RESPONSE_FILE) |
| 71 | + resp.do_not_verify = True |
| 72 | + |
| 73 | + with raises(VerificationError): |
| 74 | + resp.parse_assertion() |
| 75 | + |
| 76 | + def _get_test_response(self, path): |
| 77 | + conf = config_factory("idp", dotname("server_conf")) |
| 78 | + resp = authn_response( |
| 79 | + conf, |
| 80 | + "https://sp:443/.auth/saml/login", |
| 81 | + asynchop=False, |
| 82 | + allow_unsolicited=True, |
| 83 | + ) |
| 84 | + with open(path, "r") as fp: |
| 85 | + authn_response_xml = fp.read() |
| 86 | + resp.loads(authn_response_xml, False) |
| 87 | + return resp |
| 88 | + |
| 89 | + |
| 90 | +if __name__ == "__main__": |
| 91 | + t = TestHolderOfKeyResponse() |
| 92 | + t.setup_class() |
| 93 | + t.test_hok_response_is_parsed() |
0 commit comments